CVE-2024-5559 โ Schneider Electric PowerLogic P5
CVE-2024-5559 affects Schneider Electric PowerLogic P5 and is being exploited by the Gunra ransomware operation (a Conti-derived RaaS) to gain initial access to victim networks, per new reporting on the joint FBI/CISA Gunra advisory.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2024-5559 |
| Product | Schneider Electric PowerLogic P5 |
| Exploitation status | Exploited by Gunra ransomware for initial access (reported 2026-08-11) |
Context
Gunra gains initial access via CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy), then deploys its double-extortion locker with data published on a leak site within five to seven days of non-payment. PowerLogic P5 is an electrical power/energy-metering product; the exploitation reinforces guidance on internet-facing OT and industrial appliance patches. Gunra's victim geography is concentrated in Australia, East Asia and Europe.
Related Pages
- Gunra Ransomware Exploits Fortinet And Schneider Electric Flaws To Breach Networ โ the Gunra exploitation incident
Sources: raw/digests/Cyber-Digest-2026-08-12